NEW DELHI: Nearly 80 million players of the popular online battle game Fortnite are at increased hacking risk, said researchers from cyber security firm Check Point who discovered vulnerabilities that can give hackers access into user accounts.

If exploited, the vulnerability would enable hackers purchase virtual in-game currency using the victim's payment card details, the company said in a statement late Thursday.

The vulnerability would also have allowed for a massive invasion of privacy as an attacker could listen to in-game chatter as well as surrounding sounds and conversations within the victim's home or other location of play.

"Fortnite is one of the most popular games played mainly by kids. These flaws provided the ability for a massive invasion of privacy," said Oded Vanunu, Head of Products Vulnerability Research for Check Point.

"Together with the vulnerabilities we recently found in the platforms used by drone manufacturer DJI, show how susceptible cloud applications are to attacks and breaches," said added Vanunu.

While Fortnite players had previously been targeted by scams that deceived them into logging into fake websites that promised to generate Fortnite's 'V-Buck' in-game currency, these new vulnerabilities could have been exploited without the player handing over any login details.

Fortnite is popular on all gaming platforms, including Android, iOS, PC via Microsoft Windows and consoles such as Xbox One and PlayStation 4.

In addition to casual players, Fortnite is used by professional gamers who stream their sessions online and is popular with e-sports enthusiasts.

To fall victim to this attack, a player needs only to click on a crafted phishing link coming from an "Epic Games" domain, to make everything seem transparent, though sent by the attacker.

Once clicked, the user's Fortnite authentication token could be captured by the attacker without the user entering any login credentials.

According to the researchers, the potential vulnerability originated from flaws found in two of Epic Games' sub-domains that were susceptible to a malicious redirect, allowing users' legitimate authentication tokens to be intercepted by a hacker from the compromised sub-domain.

Check Point has notified Epic Games of the vulnerability which has now been fixed.

'Game Of Thrones' Hackathon: Here's Everything You Need To Know

of 6

Next

Prev

Play Slideshow

Another Day, Another Leak

16 Aug, 2017

It turns out you don't need hackers to spoil the next episode of Game of Thrones — HBO Spain is here for your needs! HBO Spain accidentally aired the upcoming episode titled Death Is The Enemy for an hour of its 71 minute running time, with clips surfacing on Reddit threads.
The thread in question shows a screengrab from the episode, which shows Jon Snow and Tormund Giantsbane in the snowy surroundings beyond The Wall.
(Image: YouTube)

Hacking 101

16 Aug, 2017

The hackers behind the recent massive HBO cyber attack have released a cache of the network’s internal documents, including a detailed summary of an upcoming 'GoT' episode.
The leak apparently had 7th season’s, 5th episode plot details alongside castings, script summaries and marketing materials.
The email contained nine files with labels – 'Confidential' and 'Script GOT7.'
HBO has acknowledged the hack, but has not yet given out any details about the types of files hackers were able to obtain.
(Image: http://www.hbo.com/game-of-thrones/episodes/index.html)

Treasure Trove

16 Aug, 2017

The recent security breach at HBO has led to the personal phone numbers and email addresses of some Game of Thrones actors leaking online.
Hackers broke into HBO’s systems and reportedly stole 1.5 terabytes of data, including scripts for upcoming 'GoT' episodes and two unreleased episodes of 'Ballers and Room 104.
Hackers have released 3.4GB of data, and that they’re demanding that HBO pay an undisclosed ransom to prevent further leaks.
(Image: http://www.hbo.com/game-of-thrones/episodes/index.html)

Fault In The Stars

16 Aug, 2017

In a separate incident, a 'Game of Thrones' episode leaked last week before its public TV airing. The leak wasn’t part of the HBO hack, and distribution partner Star India accidentally published it online. Either way, it’s clear HBO’s security nightmare is far from over.
(Image: http://www.hbo.com/game-of-thrones/episodes/index.html)

Dark Overlord

16 Aug, 2017

The hackers that leaked episodes from the upcoming fifth season of 'Orange Is the New Black' and episodes from Steve Harvey's newcomer 'Funderdome' are at it again. The Dark Overlord has previously held Disney and Netflix to ransom, demanding a large sum of bitcoin in return for withholding the release of stolen content. The hacker’s previously-released content has been traced back to a network breach of Larson Studios, a post-production facility in Hollywood. The Dark Overlord has also previously attempted to extort private health clinics by threatening to release sensitive patient information before subsequently publishing the information on the dark web.
(Image: http://www.hbo.com/game-of-thrones/episodes/index.html)

Next

0Comments

Want stories like this in your inbox? Sign up for the daily ET Panache newsletter.